CrowdStrike Falcon Integration
Enzoic for Active Directory v3.6
Last updated
Was this helpful?
Enzoic for Active Directory v3.6
Last updated
Was this helpful?
Enzoic for Active Directory audit events can be pushed directly to your Crowdstrike Falcon instance. This allows you to leverage the rich search capabilities built into Falcon.
From the hamburger menu at the top left, click Next-Gen SIEM, then in the flyout, click Data onboarding
Click the Data sources tab.
Click Search by name, and enter “http” (without quotes).
Click on the HEC / HTTP Event data source.
Enter the required information to setup the data source as follows
For Data source, enter enzoic-for-ad-audit-log-data-source
Select JSON as the Data type
For Connector name, enter enzoic-for-ad-audit-log-connector
In the Parsers drop down, search for and select the enzoic-enzoicforactivedirectory parser.
Tick the affirmation checkbox at the bottom, above the Cancel button.
Click Save
Click Close on the modal popup.
Towards the top right of the page, click the Generate API Key button.
On the Connection setup modal popup, copy off the API key and API URL values to a save and secure location. You will also need these to configure Enzoic for Active Directory in the next steps.
In the Enzoic for Active Directory console, click Settings in the left navigation panel, then click on the Crowdstrike tab page.
Enter the API URL and API Key generated by Falcon, tick the Enabled checkbox, then click Update Configuration.
Enzoic for Active Directory is now setup to push all audit events to your Falcon instance.